Strange logfile entries: 8/r/xff
am 15.03.2010 14:25:59 von Marten LehmannHello,
some of our users noticed, that lines like this appear in their logfiles:
58.187.78.42 - - [14/Mar/2010:04:38:53 +0100] "8\r\xff" 400 226 "-" "-"
This has been noticed be different customers on different servers. I
know that the Referer and Useragent may be empty (shown by the dash),
but URI part should at least start with GET or POST.
I found nothing with Google on "8\r\xff" but it seems that something is
talking to our servers with invalid HTTP. Is "8\r\xff" used to exploit a
webserver, but it simply didn't work out on our servers? Has anyone else
noticed such entries in the logfiles?
Kind regards
Marten
------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org